QID 995979
Date Published: 2023-11-20
QID 995979: Python (Pip) Security Update for yt-dlp (GHSA-3ch3-jhc6-5r8x)
The Generic Extractor in yt-dlp is vulnerable to an attacker setting an arbitrary proxy for a request to an arbitrary url, allowing the attacker to MITM the request made from yt-dlp's HTTP session. This could lead to cookie exfiltration in some cases.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3ch3-jhc6-5r8x for updates and patch information.
Vendor References
- GHSA-3ch3-jhc6-5r8x -
github.com/advisories/GHSA-3ch3-jhc6-5r8x
CVEs related to QID 995979
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3ch3-jhc6-5r8x | yt-dlp |
|